TWiki Viewfile Directory Traversal Vulnerability
BID:19907
CVE-2006-4294 |Info
TWiki Viewfile Directory Traversal Vulnerability
| Bugtraq ID: | 19907 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-4294 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2006 12:00AM |
| Updated: | Nov 06 2006 05:57PM |
| Credit: | Peter Thoeny is credited with the discovery of this vulnerability. |
| Vulnerable: |
TWiki TWiki 4.0.4 TWiki TWiki 4.0.3 TWiki TWiki 4.0.2 TWiki TWiki 4.0.1 TWiki TWiki 0 |
| Not Vulnerable: | |
Discussion
TWiki Viewfile Directory Traversal Vulnerability
Twiki is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.
Twiki versions 4.00 to 4.04 are vulnerable to this issue.
Twiki is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.
Twiki versions 4.00 to 4.04 are vulnerable to this issue.
Exploit / POC
TWiki Viewfile Directory Traversal Vulnerability
Attackers may exploit this vulnerability via a web client.
The following proof of concept is available:
Attackers may exploit this vulnerability via a web client.
The following proof of concept is available:
Solution / Fix
TWiki Viewfile Directory Traversal Vulnerability
Solution:
The vendor has released a hotfix to address this issue. Please see the references for more information.
Solution:
The vendor has released a hotfix to address this issue. Please see the references for more information.
References
TWiki Viewfile Directory Traversal Vulnerability
References:
References: